Novell Home

CVE-2009-5031

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-5031 at MITRE

Description

ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.

NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Novell/SUSE information

Novell Bugzilla entry: 768293

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Software Development Kit 11 SP2
  • apache2-mod_security2 >= 2.7.1-0.2.12.1
Builds
SAT Patch Nr: 7606

© 2014 Novell